people · May 16, 2026
LiteLLM Fixes CVE-2026-42208 SQL Injection Vulnerability in Proxy API Key Verification
Share the canonical public link.
LiteLLM delivered a fix for CVE-2026-42208 in version 1.83.7 by replacing string concatenation with parameterized queries. The pre-authentication SQL injection flaw in the proxy API key verification step allowed unauthenticated attackers to target stored credentials. Exploitation began approximately 36 hours after public disclosure on April 24, 2026. LiteLLM holds 45,000 GitHub stars and 7,600 forks.
Spend governor blocked model creation: provider_circuit_open (lane=dev, provider=together)